VYPR

Vendor CVEs

Jenkins Project

All CVEs

1,922 total · sorted by risk
  • CVE-2023-23848MedFeb 15, 2023
    risk 0.28cvss 4.3epss 0.01

    Missing permission checks in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in…

  • CVE-2023-25764MedFeb 15, 2023
    risk 0.28cvss 5.4epss 0.01

    Jenkins Email Extension Plugin 2.93 and earlier does not escape, sanitize, or sandbox rendered email template output or log output generated during template rendering, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or…

  • CVE-2023-25763MedFeb 15, 2023
    risk 0.28cvss 5.4epss 0.01

    Jenkins Email Extension Plugin 2.93 and earlier does not escape various fields included in bundled email templates, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control affected fields.

  • CVE-2023-25761MedFeb 15, 2023
    risk 0.28cvss 5.4epss 0.01

    Jenkins JUnit Plugin 1166.va_436e268e972 and earlier does not escape test case class names in JavaScript expressions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control test case class names in the JUnit resources processed by…

  • CVE-2023-24455MedJan 26, 2023
    risk 0.28cvss 4.3epss 0.01

    Jenkins visualexpert Plugin 1.3 and earlier does not restrict the names of files in methods implementing form validation, allowing attackers with Item/Configure permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

  • CVE-2023-24451MedJan 26, 2023
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Cisco Spark Notifier Plugin 1.1.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2023-24449MedJan 26, 2023
    risk 0.28cvss 4.3epss 0.01

    Jenkins PWauth Security Realm Plugin 0.4 and earlier does not restrict the names of files in methods implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

  • CVE-2023-24436MedJan 26, 2023
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2023-24431MedJan 26, 2023
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Orka by MacStadium Plugin 1.31 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2022-46687MedDec 12, 2022
    risk 0.28cvss 5.4epss 0.00

    Jenkins Spring Config Plugin 2.0.0 and earlier does not escape build display names shown on the Spring Config view, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to change build display names.

  • CVE-2022-46686MedDec 12, 2022
    risk 0.28cvss 5.4epss 0.00

    Jenkins Custom Build Properties Plugin 2.79.vc095ccc85094 and earlier does not escape property values and build display names on the Custom Build Properties and Build Summary pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to…

  • CVE-2022-45399MedNov 15, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Cluster Statistics Plugin 0.4.6 and earlier allows attackers to delete recorded Jenkins Cluster Statistics.

  • CVE-2022-45398MedNov 15, 2022
    risk 0.28cvss 4.3epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins Cluster Statistics Plugin 0.4.6 and earlier allows attackers to delete recorded Jenkins Cluster Statistics.

  • CVE-2022-45394MedNov 15, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Delete log Plugin 1.0 and earlier allows attackers with Item/Read permission to delete build logs.

  • CVE-2022-45390MedNov 15, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins loader.io Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2022-45387MedNov 15, 2022
    risk 0.28cvss 5.4epss 0.01

    Jenkins BART Plugin 1.0.3 and earlier does not escape the parsed content of build logs before rendering it on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability.

  • CVE-2022-45382MedNov 15, 2022
    risk 0.28cvss 5.4epss 0.01

    Jenkins Naginator Plugin 1.18.1 and earlier does not escape display names of source builds in builds that were triggered via Retry action, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to edit build display names.

  • CVE-2022-45380MedNov 15, 2022
    risk 0.28cvss 5.4epss 0.01

    Jenkins JUnit Plugin 1159.v0b_396e1e07dd and earlier converts HTTP(S) URLs in test report output to clickable links in an unsafe manner, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

  • CVE-2022-43434MedOct 19, 2022
    risk 0.28cvss 5.3epss 0.01

    Jenkins NeuVector Vulnerability Scanner Plugin 1.20 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.

  • CVE-2022-43433MedOct 19, 2022
    risk 0.28cvss 4.3epss 0.01

    Jenkins ScreenRecorder Plugin 0.7 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.

  • CVE-2022-43432MedOct 19, 2022
    risk 0.28cvss 4.3epss 0.01

    Jenkins XFramium Builder Plugin 1.0.22 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.

  • CVE-2022-43428MedOct 19, 2022
    risk 0.28cvss 5.3epss 0.01

    Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller…

  • CVE-2022-43424MedOct 19, 2022
    risk 0.28cvss 5.3epss 0.01

    Jenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller…

  • CVE-2022-43422MedOct 19, 2022
    risk 0.28cvss 5.3epss 0.01

    Jenkins Compuware Topaz Utilities Plugin 1.0.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process.

  • CVE-2022-43420MedOct 19, 2022
    risk 0.28cvss 5.4epss 0.01

    Jenkins Contrast Continuous Application Security Plugin 3.9 and earlier does not escape data returned from the Contrast service when generating a report, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control or modify Contrast…

  • CVE-2022-43414MedOct 19, 2022
    risk 0.28cvss 5.3epss 0.01

    Jenkins NUnit Plugin 0.27 and earlier implements an agent-to-controller message that parses files inside a user-specified directory as test results, allowing attackers able to control agent processes to obtain test results from files in an attacker-specified directory on the…

  • CVE-2022-43411MedOct 19, 2022
    risk 0.28cvss 5.3epss 0.01

    Jenkins GitLab Plugin 1.5.35 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.

  • CVE-2022-43410MedOct 19, 2022
    risk 0.28cvss 5.3epss 0.01

    Jenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or scheduled for polling through its webhook endpoint, including jobs the user has no permission to access.

  • CVE-2022-43409MedOct 19, 2022
    risk 0.28cvss 5.4epss 0.01

    Jenkins Pipeline: Supporting APIs Plugin 838.va_3a_087b_4055b and earlier does not sanitize or properly encode URLs of hyperlinks sending POST requests in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create Pipelines.

  • CVE-2022-41252MedSep 21, 2022
    risk 0.28cvss 4.3epss 0.01

    Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allows users with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.

  • CVE-2022-41251MedSep 21, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Apprenda Plugin 2.2.0 and earlier allows users with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2022-41247MedSep 21, 2022
    risk 0.28cvss 4.3epss 0.01

    Jenkins BigPanda Notifier Plugin 1.4.0 and earlier stores the BigPanda API key unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

  • CVE-2022-41240MedSep 21, 2022
    risk 0.28cvss 5.4epss 0.01

    Jenkins Walti Plugin 1.0.1 and earlier does not escape the information provided by the Walti API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide malicious API responses from Walti.

  • CVE-2022-41229MedSep 21, 2022
    risk 0.28cvss 5.4epss 0.01

    Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.134 and earlier does not escape configuration options of the Execute NetStorm/NetCloud Test build step, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure…

  • CVE-2022-41225MedSep 21, 2022
    risk 0.28cvss 5.4epss 0.01

    Jenkins Anchore Container Image Scanner Plugin 1.0.24 and earlier does not escape content provided by the Anchore engine API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control API responses by Anchore engine.

  • CVE-2022-41224MedSep 21, 2022
    risk 0.28cvss 5.4epss 0.01

    Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control tooltips for this…

  • CVE-2022-38664MedAug 23, 2022
    risk 0.28cvss 5.4epss 0.01

    Jenkins Job Configuration History Plugin 1165.v8cc9fd1f4597 and earlier does not escape the job name on the System Configuration History page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure job names.

  • CVE-2022-36919MedJul 27, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2022-36918MedJul 27, 2022
    risk 0.28cvss 4.3epss 0.01

    Jenkins Buckminster Plugin 1.1.1 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

  • CVE-2022-36917MedJul 27, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Google Cloud Backup Plugin 0.6 and earlier allows attackers with Overall/Read permission to request a manual backup.

  • CVE-2022-36914MedJul 27, 2022
    risk 0.28cvss 4.3epss 0.01

    Jenkins Files Found Trigger Plugin 1.5 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

  • CVE-2022-36913MedJul 27, 2022
    risk 0.28cvss 4.3epss 0.01

    Jenkins Openstack Heat Plugin 1.5 and earlier does not perform permission checks in methods implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

  • CVE-2022-36912MedJul 27, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Openstack Heat Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.

  • CVE-2022-36910MedJul 27, 2022
    risk 0.28cvss 5.4epss 0.01

    Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to reindex the database and to obtain information about jobs otherwise inaccessible to them.

  • CVE-2022-36904MedJul 27, 2022
    risk 0.28cvss 4.3epss 0.01

    Jenkins Repository Connector Plugin 2.2.0 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

  • CVE-2022-36903MedJul 27, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Repository Connector Plugin 2.2.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2022-36898MedJul 27, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins.

  • CVE-2022-36890MedJul 27, 2022
    risk 0.28cvss 4.3epss 0.01

    Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the name of files in methods implementing form validation, allowing attackers with Item/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file…

  • CVE-2022-36885MedJul 27, 2022
    risk 0.28cvss 5.3epss 0.01

    Jenkins GitHub Plugin 1.34.4 and earlier uses a non-constant time comparison function when checking whether the provided and computed webhook signatures are equal, allowing attackers to use statistical methods to obtain a valid webhook signature.

  • CVE-2022-36884MedJul 27, 2022
    risk 0.28cvss 5.3epss 0.01

    The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to use an attacker-specified Git repository.

Page 27 of 39